DUGGANUSA · Findings
Live · Searchable · 1.13M+ IOC corpus

Known Compromised MCP / Version / Dependency Combinations

The full Dredd findings index. Server names, versions, and dependencies that have been flagged by the DugganUSA threat-intel corpus or independent disclosures from Socket, Aikido, GitGuardian, ReversingLabs, Phylum, StepSecurity, Wiz, and URLhaus. Free to search, no auth.

Loading…
Severity Server Version / Dep Family Source Detected
  loading findings…

Verify the chain end-to-end

Test fixture is always present. Query /api/v1/dredd/preflight?server=dredd-test-known-bad-mcp — should return verdict BLOCK / severity critical. If that round-trips correctly your installation is wired right.

Or query for any real entry from the table above — the preflight call accepts the same server names you see here.